Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-12-01 09:03
Updated : 2018-10-19 08:39
NVD link : CVE-2005-3962
Mitre link : CVE-2005-3962
JSON object : View
CWE
CWE-189
Numeric Errors
Products Affected
perl
- perl